Veeam Backup & Replication
Our sources currently list 42 known vulnerabilities affecting Veeam Backup & Replication. 13 are rated critical severity. 4 of 42 are actively exploited according to CISA, the most recent added 17 October 2024.
Last updated: 22 July 2026, 20:37 AEST
No current ASD advisory names this product.That describes the Australian Signals Directorate’s publication record — it is not a statement that this product is free of vulnerabilities. See the list below.
| CVE | Severity | Exploitation | Published | Summary |
|---|---|---|---|---|
| CVE-2024-40711 | Critical (9.8) | Actively exploited · ransomware | A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE). | |
| CVE-2023-27532 | High (7.5) | Actively exploited · ransomware | Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backu… | |
| CVE-2022-26500 | High (8.8) | Actively exploited · ransomware | Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers… | |
| CVE-2022-26501 | Critical (9.8) | Actively exploited · ransomware | Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2). | |
| CVE-2025-23120 | High (8.8) | Elevated likelihood (22%) | A vulnerability allowing remote code execution (RCE) for domain users. | |
| CVE-2024-29849 | Critical (9.8) | Elevated likelihood (17%) | Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface. | |
| CVE-2024-42455 | High (8.1) | Elevated likelihood (15%) | A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserialization by sending a serialized temporary fi… | |
| CVE-2025-23121 | High (8.8) | Elevated likelihood (12%) | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user | |
| CVE-2025-24286 | High (7.2) | Elevated likelihood (11%) | A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code. | |
| CVE-2022-26504 | High (8.8) | No exploitation reported | Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (SCVMM) allows attackers execute… | |
| CVE-2025-59470 | Critical (9.0) | No exploitation reported | This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter. | |
| CVE-2026-21671 | Critical (9.1) | No exploitation reported | A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Rep… | |
| CVE-2021-35971 | Critical (9.8) | No exploitation reported | Veeam Backup and Replication 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 mishandles deserialization during Microsoft .NET remoting. | |
| CVE-2026-21669 | Critical (9.9) | No exploitation reported | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. | |
| CVE-2025-59468 | Critical (9.0) | No exploitation reported | This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter. | |
| CVE-2026-21666 | Critical (9.9) | No exploitation reported | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. | |
| CVE-2026-21667 | Critical (9.9) | No exploitation reported | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. | |
| CVE-2024-40710 | High (8.8) | No exploitation reported | A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcreden… | |
| CVE-2026-21708 | Critical (9.9) | No exploitation reported | A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user. | |
| CVE-2020-15518 | High (8.8) | No exploitation reported | VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, which allows unprivileged users to achieve total control over… | |
| CVE-2025-48984 | High (8.8) | No exploitation reported | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. | |
| CVE-2024-29851 | High (7.2) | No exploitation reported | Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account. | |
| CVE-2024-39718 | High (8.1) | No exploitation reported | An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service account. | |
| CVE-2024-29850 | High (8.8) | No exploitation reported | Veeam Backup Enterprise Manager allows account takeover via NTLM relay. | |
| CVE-2025-55125 | High (7.8) | No exploitation reported | This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file. | |
| CVE-2025-48983 | Critical (9.9) | No exploitation reported | A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user. | |
| CVE-2024-40717 | High (8.8) | No exploitation reported | A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These jobs can be co… | |
| CVE-2024-40715 | High (7.7) | No exploitation reported | A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypass. Attackers must be able to perform Man… | |
| CVE-2025-59469 | Critical (9.0) | No exploitation reported | This vulnerability allows a Backup or Tape Operator to write files as root. | |
| CVE-2024-29852 | Low (2.7) | No exploitation reported | Veeam Backup Enterprise Manager allows high-privileged users to read backup session logs. | |
| CVE-2026-21668 | High (8.8) | No exploitation reported | A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository. | |
| CVE-2015-5742 | Low (2.1) | No exploitation reported | VeeamVixProxy in Veeam Backup & Replication (B&R) before 8.0 update 3 stores local administrator credentials in log files with world-readable permissions, which allows local users … | |
| CVE-2024-42452 | High (8.8) | No exploitation reported | A vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and obtain credentials, effectively escalating privileges to sy… | |
| CVE-2024-42457 | Medium (6.5) | No exploitation reported | A vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by leveraging a combination of methods in a remote management int… | |
| CVE-2026-21670 | High (7.7) | No exploitation reported | A vulnerability allowing a low-privileged user to extract saved SSH credentials. | |
| CVE-2024-42456 | High (8.8) | No exploitation reported | A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates critical configuration settings, such as m… | |
| CVE-2024-45204 | Medium (4.3) | No exploitation reported | A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves u… | |
| CVE-2024-40714 | High (8.3) | No exploitation reported | An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations. | |
| CVE-2024-42453 | High (8.1) | No exploitation reported | A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts. This includes the ability to … | |
| CVE-2024-40713 | High (7.8) | No exploitation reported | A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA. | |
| CVE-2024-40712 | High (7.8) | No exploitation reported | A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation (LPE). | |
| CVE-2024-42451 | Medium (6.5) | No exploitation reported | A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. This is achieved by calling a series of methods over an extern… |
Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.
Let's talk
4 of these are being actively exploited right now.
Our Newcastle team can audit your Veeam estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.
